Sha256: a73827dbcd4c6e7a1ffd3741a66dd493e82cd13a46486a6035bb6c467f73310d

Contents?: true

Size: 495 Bytes

Versions: 1

Compression:

Stored size: 495 Bytes

Contents

---
gem: rubygems-update
library: rubygems
cve: 2017-0899
url: http://blog.rubygems.org/2017/08/27/2.6.13-released.html
title: RubyGems ANSI escape sequence vulnerability
date: 2017-08-29
description: |
  RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem
  specifications that include terminal escape characters. Printing the gem
  specification would execute terminal escape sequences.
cvss_v2: 7.5
patched_versions:
  - ">= 2.4.5.3"
  - ">= 2.5.2.1"
  - ">= 2.6.13"

Version data entries

1 entries across 1 versions & 1 rubygems

Version Path
bundler-audit-0.7.0.1 data/ruby-advisory-db/gems/rubygems-update/CVE-2017-0899.yml